it analyst temco logistics

Naod Michael

I find root causes instead of treating symptoms, I automate the manual work, and I ship real systems.

scroll
[01]

Measured impact

from the work, real numbers
+
vulnerability instances closed the same day the fix landed
%
devices patched in one day, up from 43%
%
of open vulnerabilities came from 97 abandoned machines
CVE instances contained and root-caused
automated tests that caught 3 bugs standard testing missed
[02]

Certifications

giac / cloud / google
GFACT96%
GSEC93%
Google Cybersecuritycertified
AWS Cloud Practitionercertified
GCIHin progress
[03]

Selected work

problem / action / result

Fleet-wide Chrome vulnerability exposure closed in one day

case / 01chrome remediation
the problem

An EY security assessment flagged 529,644 Chrome vulnerabilities across 1,449 devices, 66% of everything it found. The cause was architectural. Two conflicting Chrome update rules in Workspace ONE pushed different versions to the same devices, and Chrome's built-in updater had silently stopped working on affected machines, in some cases for up to two years.

what I did

I removed the conflicting rules, cleaned duplicate and stale Chrome entries out of the device catalog, and put one enforced update policy in place fleet-wide, so Chrome updates no longer depend on the browser's own updater. I delivered an executive brief on the remediation to leadership.

the result

Same day, devices on the fixed version went from 751 to 1,389 (43% to 80% of the 1,728 targeted), closing roughly 507,000 of the ~523,000 credited vulnerability instances.

Workspace ONE architecture gap: 46% of fleet vulnerabilities traced to 97 abandoned machines

case / 02endpoint architecture
the problem

A Workspace ONE Windows Update profile was reaching 130 of 1,737 devices. The cause turned out to be architectural, not a misconfiguration.

what I did

A test profile proved it: CSP and OMA-DM profiles only reach the 123 UEM Managed endpoints, while ADMX profiles through Intelligent Hub reach all 1,730. Every OMA-DM profile in the tenant, Win-Firewall included, had been covering 7% of the fleet, and Intune, not Workspace ONE, is the real MDM authority for 1,608 devices. I joined four data sources (CrowdStrike Falcon, Intune, Entra ID, and Workspace ONE) to classify all 1,696 Windows endpoints, then delivered an executive brief, a profile-type training guide for the other analysts, and a workbook splitting the 107 machines worth retiring from the 328 still in daily use.

the result

97 abandoned computers, 6% of the fleet, were generating 46% of the 171,307 open vulnerabilities. There was no device retirement process to catch them: 160 staff still held 357 computers between them, one person nine.

Rebuilt Pheme on Cloudflare Workers with a zero-loss cutover

case / 03cloudflare workers
the problem

The company's live-call dashboard needed a full rebuild on Cloudflare Workers, a runtime that is stateless and event driven, with no persistent process, filesystem, or long-lived memory. The old system's Node.js assumptions do not survive there.

what I did

I reworked process lifecycle, storage, scheduling, and WebSocket transport around how Workers actually execute, keeping every business rule and threshold from the old system intact. I stood up production: Durable Object-backed state, KV storage, and Cloudflare Access with Entra ID SSO. Then I wrote a 122-test automated suite that runs against the live Workers runtime.

the result

The suite caught 3 runtime-specific bugs that standard testing never would have, and I diagnosed each one from live production logs. The cutover from the legacy system lost nothing: live-call visibility stayed continuous across 158 locations doing 10,000+ calls a day, verified against real call traffic after launch. The app is internal to Temco, gated by Entra ID SSO, and live at pheme.temco.ai.

15,461 CVE instances contained on 7 endpoints

case / 04incident response
the problem

Seven endpoints carried 15,461 CVE instances: 16.5% of total fleet exposure (93,858 across 87 devices) on 8% of machines, 2.25x the fleet norm. 357 of those CVEs existed nowhere else in the environment.

what I did

I applied reversible containment controls per playbook first, then traced the root cause: seven devices that had never finished the existing decommissioning process, five of them superseded hardware. I used the Nagomi asset export to quantify exposure per device.

the result

All seven endpoints contained, with reversible controls throughout. The real finding was the decommissioning process, and I packaged the analysis into an executive summary for director review.

[04]

Builds

things i shipped
b/01

Pheme

A live-call operations dashboard on Cloudflare Workers covering 158 locations doing 10,000+ calls a day.

internal / entra id gatedcloudflare workers
b/02

Printer provisioning chatbot

A self-service flow that adds the right printer to your device in one chat exchange, triggering scripts across Workspace ONE, Domotz Pro, and Power Automate.

in progressworkspace one / domotz / power automate
b/03

Caller ID automation

A Dialpad API script that set department-matched caller ID for every office and warehouse clerk line in one sync.

livedialpad api
[05]

Contact

open to the conversation

Reach me at nmichaelcyber@gmail.com

linkedin.com/in/naodmichael → naod michael / it analyst, temco logistics